Get in Touch

Course Outline

DAY 1: Fundamentals of ISO/IEC 27017 & Framework, Cloud Risk & Control

  • Module 1: Introduction to ISO/IEC 27017 – Overview, its relationship with ISO/IEC 27001/27002, and core objectives.
  • Module 2: Scope of ISO/IEC 27017 – Additional controls, cloud environments, and audit boundaries.
  • Module 3: ISO/IEC 27017 Certification Scheme – Understanding the certification model as an extension of ISO/IEC 27001.
  • Module 4: ISO/IEC 27017 Auditor Competency Model – Essential competencies, cloud technical knowledge, and risk-based thinking.
  • Module 5: Cloud-Specific Risk Examples – Risks associated with VM management, multi-tenancy, isolation, and legal jurisdictions.
  • Module 6: Cloud Service Categories – Discussing audit implications for SaaS, PaaS, IaaS, NaaS, and DSaaS.
  • Module 7: ISO/IEC 27017 Specific Controls – Shared responsibilities, VM hardening, and monitoring cloud services.
  • Module 8: Control Mapping to Cloud Services – Mapping controls to IAM, Cloud Logging, Cloud KMS, and VPC.

DAY 2: Technical Audit Simulation & Regulatory Integration

  • Module 9: Audit Simulation Planning – Defining the audit scope (GCP/Organization) and selecting resource samples.
  • Module 10: Cloud Control Audit Simulation (Hands-on) – Auditing Access Control, Resource Configuration, and Security Posture using real evidence.
  • Module 11: Cloud Regulations & Compliance Requirements
    • Indonesia Cloud Regulations: Deep dive into POJK 11/2022 & PADK No. 1 Year 2026 regarding Information Technology Implementation by Commercial Banks.
    • Mapping: Aligning ISO/IEC 27017 controls directly to local banking compliance requirements.
  • Module 12: ISO/IEC 27017 Certification Audit Process – Techniques, methodology, and lifecycle of audits.
  • Module 13: Integrated Audit Guidance – Comparing ISO/IEC 27001, 27017, and 27018.
  • Module 14: Final Workshop – Conducting an end-to-end audit simulation, preparing findings, and presenting results.

Requirements

  • Fundamental understanding of IT Security.
  • Practical experience with IT Security and Cloud Platforms.

Target Audience

  • IT Security professionals within banking institutions.
  • IT Security personnel at other financial organizations.
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories